GDPR Articles 82-83 and AKI Enforcement in Estonia
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 15 January 2019.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect AKI to pursue a General Data Protection Regulation (GDPR) fine against your processing of personal data of a person in Estonia through a misdemeanor proceeding rather than a direct administrative sanction.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
IKS Section 71 itself establishes that more serious personal-data violations are carved out of the misdemeanour (vaartegu) scheme entirely: its own EUR 800 fine applies only where the conduct does not meet the elements of the offences set out in Penal Code (karistusseadustik) Sections 157 and 157^1, meaning conduct meeting those elements is instead a criminal matter (kuritegu) prosecuted under the Penal Code rather than adjudicated by AKI as a misdemeanour. The offence elements and penalty terms of Penal Code Sections 157 and 157^1 are not reproduced here, so no imprisonment figure is asserted; IKS Section 71's own cross-reference is the basis for this criminal_exposure finding.
Penalty structure
Unusually among EU member states, Estonia's Isikuandmete kaitse seadus (Personal Data Protection Act, IKS) restates the GDPR Article 83 fine ceiling directly in its own text rather than relying solely on the Regulation's direct effect, and classifies the resulting penalty as an Estonian misdemeanour (vaartegu) rather than a separate administrative-fine category. Sections 66 to 70 each punish a distinct category of GDPR violation (data subject rights under Articles 12 to 22, unlawful transfer under Articles 44 to 49, violations of this Act's own processing bases, non-compliance with an Andmekaitse Inspektsioon (AKI) order under Article 58(2), and obstructing AKI access under Article 58(1)) with a fine of up to EUR 20,000,000, or, where the offender is a legal person, up to EUR 20,000,000 or 4 percent of its preceding financial year's worldwide annual turnover, whichever is greater, mirroring GDPR Article 83(5)-(6)'s own ceiling. Sections 71 and 72 set a much smaller residual misdemeanour fine, up to 200 fine units (approximately EUR 800), for unlawful personal-data access by an employee outside their duties, or any other data protection violation, that does not meet the elements of a Penal Code offence (see criminal_exposure_note) or of Sections 62 to 71.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Andmekaitse Inspektsioon (AKI), Estonia's supervisory authority under the GDPR, which under IKS Section 73 is also the extrajudicial adjudicator (kohtuvaline menetleja) of the misdemeanours (vaarteod) IKS Chapter 6 (Sections 62 to 72) creates.
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Estonian Data Protection Inspectorate (AKI) is the supervisory authority.
Estonian law does not recognize an administrative fine in the ordinary sense used elsewhere in the EU; Isikuandmete kaitse seadus Sections 66 to 70 and 73 instead make AKI itself the extrajudicial adjudicator of a General Data Protection Regulation (GDPR) Article 83 fine as an Estonian misdemeanor (vaartegu), applying the GDPR's own EUR 20,000,000 or 4 percent ceiling directly; a 2023 amendment reported by secondary commentary to have extended the limitation period is not independently confirmed against primary legislative text.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsprocesses_biometricsprocesses_voice
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
secondary commentary on Estonia's misdemeanor-track fine mechanism, not independently confirmed against primary legislative text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.